github nicobailon/pi-mcp-adapter v3.3.0

4 hours ago

This release gives you more control over which MCP tools can run without asking. You can now see whether a server says a tool only reads data or may delete it, and a new approveTools: "destructive" setting asks before any tool that might change something, without listing tool names. Tool calls no longer time out while you are still filling in a server's input form. The model also gets a better sense of what tools return, and prompt slash commands suggest argument names as you type.

Highlights

  • See whether a tool is read-only or destructive when you describe it and in the approval prompt.
  • Set approveTools: "destructive" to be asked before any tool that may change or delete data.
  • Answering a server's input form no longer makes the tool call fail with "Request timed out".
  • For tools with no output schema, the model can see the result shape from earlier calls in the session.
  • MCP prompt slash commands suggest argument names as you type.

Need to know

A mistyped approveTools value used to turn approval off without saying so. It now asks before every tool. If you start getting approval prompts you didn't expect after upgrading, check that approveTools is true, false, "destructive", or a list of tool name patterns.

Highlights

  • You can now tell a read-only MCP tool from one that deletes data. The hints servers declare on their tools show up when you describe a tool and in the approval prompt.
  • New approveTools: "destructive" setting asks before any tool that may change or delete data, without making you list tool names.
  • A tool call no longer fails with "Request timed out" while you are still answering the server's input form.
  • The model gets a better idea of what a tool returns, even when the server declares no output schema.
  • MCP prompt slash commands now suggest argument names as you type.

Added

  • The hints a server declares on its tools (read-only, destructive, idempotent, open-world, title) are now kept, including in the metadata cache, and shown in mcp({ describe }), in tools.describe inside mcpScript, and in the tool approval prompt. Search results and direct-tool descriptions stay the same, so nothing is added to every turn's context.
  • approveTools: "destructive" asks before any tool that may change or delete data. Only tools the server marks read-only or non-destructive run without a prompt; tools with no hints still ask. It works globally or per server.
  • For tools that declare no output schema, mcp({ describe }) and tools.describe in mcpScript now show the output shape seen so far this session, after a successful call returns structured content or a JSON text result. Only field names and types are shown, never values. The shape is kept in memory only and is labeled as observed, not a contract.
  • MCP prompt slash commands now suggest declared argument names as you type. Arguments you already entered are kept, suggestions follow the server's latest prompt list, and nothing connects to a server just to show them. Thanks to @quifox for PR #733.
  • Jev semantic search works with an existing OpenRouter key. Set SYSTEMONE_ENDPOINT=https://openrouter.ai/api/alpha/decisions and OPENROUTER_API_KEY is used as the key, with the model defaulting to typesafe/jev-1.13. The key is never sent to any other endpoint.

Changed

  • A mistyped approveTools value no longer turns approval off silently. Any value other than true, false, "destructive", or a list of tool name patterns now asks before every tool.
  • Dropped the unused @modelcontextprotocol/ext-apps dependency. MCP Apps already run from a bundled app bridge, and the package made a plain npm install pull in the old MCP SDK v1 and its HTTP server dependencies.

Fixed

  • A tool call no longer times out while you are answering the server's input prompt. The request timeout (60 seconds by default) kept running while the form was open, so a slow answer failed the call with "Request timed out" and the answer was lost. The timeout now pauses while the prompt is open.
  • Jev no longer rejects responses that carry extra provider details, such as OpenRouter's id, provider, and usage.cost. The documented OpenRouter setup previously failed with "Jev returned an invalid response."
  • Typechecking the adapter's sources with @types/node 25 no longer fails in the Unix socket transport. Thanks to @abdwhb-png for PR #732.

Don't miss a new pi-mcp-adapter release

NewReleases is sending notifications on new releases.